What we collect, why, and how we protect it.
Friendly HR Professional™ is People Focused • Confidential • Supportive. This page explains what data we collect, how we use it, who we share it with (Stripe, our email provider, and that’s it), and how to exercise your rights. Plain language, no legalese — still have questions? Email us.
1. What This Policy Covers
This Privacy Policy covers Friendly HR Professional™ (“the Service”) operated by Friendly HR Professional™ and the website at https://friendlyhrpro.com. It applies to information we collect when you visit the site, sign up for a subscription, buy a document, book a Director session, ask the AI a question, or email us.
Effective date: 2026-07-29. Last updated: 2026-07-29.
2. Information We Collect
Account & subscription data
When you subscribe, your email, Stripe customer ID, Stripe subscription ID, plan tier, billing cycle, and current period dates are recorded so we can grant access, send receipts, and re-issue download links. We are notified when your subscription starts, cancels, or fails to renew via a Stripe webhook.
Booking data
When you book a Director session from the /session page, we record your name, email, the question you
share ahead of the call, the slot you picked from the published DIRECTOR_PUBLIC_BOOKING_SLOTS list, and the
confirmation status after payment.
Lead magnet data
The HR Survival Guide funnel captures your email and any UTM parameters sent from the source (TikTok, Instagram, etc.) so we can deliver the guide you signed up for.
AI chat data
Questions you submit to Ask Friendly HR AI are routed to our AI provider to generate a response. Responses are gated by an active subscription.
Usage counters
Per-feature monthly counters — AI questions, document downloads, catalog templates, knowledge-base articles — are stored
per period_month (YYYY-MM) so we can enforce your tier’s monthly limits.
Automatically collected
Standard server logs (timestamp, IP address, user-agent, request path) are kept for 30 days for security and abuse-investigation purposes. A privacy-friendly analytics pixel from Polsia Analytics records anonymised visit events.
Cookies
First-party cookies only:
- stripe_cid — your Stripe customer ID, used to recognise repeat subscribers across requests.
- A Polsia analytics cookie for anonymous visit attribution.
- Cloudflare may set cookies for security and routing; we don’t read them on the server.
3. How We Use Your Information
We use the data described above to:
- Deliver the Service you signed up for — templates, AI responses, Director sessions, knowledge articles.
- Send transactional email — purchase receipts, session confirmations, Director reminders, AI follow-ups (only if you opted in).
- Enforce your plan’s monthly limits.
- Detect and prevent abuse — scraping, account sharing, payment fraud.
- Respond to support requests.
We do not sell, rent, or share your data with third parties beyond Stripe (payment processing), our email-delivery provider (transactional email), and our analytics provider. No ad networks, no marketing data brokers, no “audience insights.”
4. Payments & Stripe
All payments are processed by Stripe. When you check out, your card details go directly to Stripe — we never see or store your full card number on our servers.
What we do store after checkout: your Stripe customer ID, subscription tier, current status, current period start/end dates, and the Stripe charge ID for receipts. Stripe’s own Privacy Policy applies to the data they collect during checkout.
5. Email
We send transactional email only by default:
- Purchase receipts and signed download links.
- Director session confirmations (.ics) and 24-hour reminders.
- Subscription confirmations, renewals, and cancellation acknowledgements.
Marketing email is sent only via the welcome sequence (a series of 4–6 onboarding emails you can unsubscribe from at any time with one click) and is opt-in. Every marketing email includes an unsubscribe link. We never sell, rent, or share email lists.
6. Digital Product Delivery
When you buy a PDF or template, the delivery email contains a 15-minute HMAC-signed download URL scoped to your email. The link:
- expires 15 minutes after it was minted,
- can’t be shared — it’s bound to your email,
- and doesn’t expose the underlying R2 file URL.
We never put public, permanent links in transactional email.
7. AI & Model Providers
AI chat responses route through the Polsia Agent API. Friendly HR Professional™ does not call OpenAI, Anthropic, or any other AI provider directly with your data. Questions you submit are processed for the response only — they are not retained for model training.
8. Data Retention
- Active subscriptions — kept for the life of the account.
- Cancelled subscriptions — kept for 24 months so we can re-issue receipts and answer refund questions, then deleted.
- PDF purchase records — tied to email, kept indefinitely for tax and audit purposes.
- AI chat history — the server-side record of questions and responses is deleted after 90 days.
- Session bookings — deleted after 12 months.
- Lead-magnet emails — kept until you unsubscribe via the link in any of our emails.
- Server logs — 30 days.
9. Your Rights (GDPR, CCPA, and equivalents)
You have the right to:
- Access a copy of the personal data we hold about you.
- Correct inaccurate data.
- Delete your data (subject to the retention rules in §8).
- Portability — receive your data in a machine-readable format.
- Opt out of any “sale” of personal information (we don’t sell).
To exercise any of these, email us. We respond within 30 days. California residents have additional rights under the CCPA / CPRA — the “right to know,” the “right to delete,” and the “right to opt out of sale” — we honour all three.
10. Security
We protect your data with the same measures we’d want as customers:
- HTTPS everywhere — the site is end-to-end encrypted.
- HMAC-signed download URLs with 15-minute expiry — no public, guessable, or permanent file links anywhere.
- No card data on our servers — Stripe handles it directly.
- Private R2 storage for PDFs — files are served only via signed URLs. Public caches and direct object URLs are not used.
11. Children’s Privacy
The Service is not directed at children under 16, and we do not knowingly collect personal information from anyone under 16. If you believe a child has submitted data to us, email us and we will delete it.
12. Changes
Posting a new “Last updated” date at the bottom of this page constitutes notice. For material changes (a new sub-processor, a new category of data collected, etc.) we’ll also send a notice to active subscribers via support email.
13. Contact & Data Protection Officer
Privacy questions, data requests, or concerns: friendlyhr@polsia.app.
Last updated: 2026-07-29